Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.security > #6329

Re: CVE applicability

From Salvatore Bonaccorso <carnil@debian.org>
Newsgroups linux.debian.security
Subject Re: CVE applicability
Date 2024-06-19 08:00 +0200
Message-ID <IQWwp-3XTu-11@gated-at.bofh.it> (permalink)
References <IQMdH-3RwF-9@gated-at.bofh.it> <IQMdH-3RwF-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Hi,

On Wed, Jun 19, 2024 at 12:04:45AM +0530, Arul Anand MM wrote:
> Hello Debian Security Team,
> 
> This is regarding Debian advisory
> https://security-tracker.debian.org/tracker/CVE-2023-3390.
> 
> I would like to confirm whether version 5.10.191-1 is impacted by the UAF
> and LPE.
> 
> Advisory page on September 14
> https://web.archive.org/web/20230924174231/https://security-tracker.debian.org/tracker/CVE-2023-3390
> states the issue is fixed in 5.10.191-1 but the current version of advisory
> states "5.10.209-2" as the fixed version. Is there any information on the
> impacted version changes for CVE-2023-3390?

All the version information required is actually on
https://security-tracker.debian.org/tracker/CVE-2023-3390 . In the
lower table you see where the fix landed, In the table above you see
the current available versions in the suites, with their status.

But maybe I'm missunderstanding the question?

Regards,
Salvatore

Back to linux.debian.security | Previous | NextPrevious in thread | Next in thread | Find similar


Thread

CVE applicability Arul Anand MM <arulanandkk1@gmail.com> - 2024-06-18 21:00 +0200
  Re: CVE applicability Salvatore Bonaccorso <carnil@debian.org> - 2024-06-19 08:00 +0200
  Re: CVE applicability Thomas Hochstein <thh@thh.name> - 2024-06-19 23:50 +0200

csiph-web